935
VMScore

CVE-2017-8682

Published: 13/09/2017 Updated: 10/05/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an malicious user to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 1511

microsoft windows 10 1703

microsoft windows server 2012 -

microsoft windows server 2016 -

microsoft windows 8.1 -

microsoft windows rt 8.1 -

microsoft windows server 2008 -

microsoft windows server 2008 r2

microsoft office 2007 -

microsoft office 2010 -

microsoft office word viewer -

microsoft windows 10 -

microsoft windows 10 1607

microsoft windows 7 -

microsoft windows server 2012 r2

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=1273 We have encountered a number of Windows kernel crashes in the win32ksys driver while processing corrupted TTF font files The most frequent one occurring for the bug reported here is as follows: --- PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced T ...